UCF STIG Viewer Logo

The system must ensure uniqueness of CHAP authentication secrets.


Overview

Finding ID Version Rule ID IA Controls Severity
V-39303 SRG-OS-99999-ESXI5-000147 SV-51119r1_rule Low
Description
The mutual authentication secret for each host must be different and the secret for each client authenticating to the server must be different as well. This ensures if a single host is compromised, an attacker cannot create another arbitrary host and authenticate to the storage device. With a single shared secret, compromise of one host can allow an attacker to authenticate to the storage device.
STIG Date
VMware ESXi Server 5.0 Security Technical Implementation Guide 2017-01-06

Details

Check Text ( C-46567r3_chk )
From the vSphere Client, select the host, and then choose: Configuration - Storage Adaptors - iSCSI Initiator Properties - CHAP - CHAP
(Target Authenticates Host) - determine if a different authentication secret is configured for each ESXi host.

If a different authentication secret is not configured for each ESXi host, this is a finding.

If iSCSI is not used, this is not a finding.
Fix Text (F-44282r3_fix)
From the vSphere Client, select the host, and then choose: Configuration - Storage Adaptors - iSCSI Initiator Properties - CHAP - CHAP
(Target Authenticates Host) - configure the authentication secret.